CVE-2026-22732CRITICAL 9.1EPSS p38.9%
CVE-2026-22732CVE-2026-22732
Description
When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written.
This issue affects Spring Security Servlet applications using lazy (default) writing of HTTP Headers:
: from 5.7.0 through 5.7.21, from 5.8.0 through 5.8.23, from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.8, from 7.0.0 through 7.0.3.
Scoring
| CVSS 3.1 | 9.1 (CRITICAL) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
| EPSS | 0.48% probability of exploitation · percentile 38.9% · 2026-08-03T12:00:16Z |
| Published | 2026-03-19 |
| Last modified | 2026-04-16 |
Underlying weaknesses· 1
References
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Direct Request ('Forced Browsing')cwe-425 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.